9794257

Managing Secure Sharing of Private Information Across Security Domains by Individuals Having a Service Authorization

PublishedOctober 17, 2017
Assigneenot available in USPTO data we have
Technical Abstract

Patent Claims
36 claims

Legal claims defining the scope of protection. Each claim is shown in both the original legal language and a plain English translation.

Claim 1

Original Legal Text

1. A method of requesting a service authorization from a regulating or funding organization for a service provider in at least a first organization to provide service to one or more individuals in a second organization, the method comprising: (a) storing, by one or more physical nodes, a database comprising information pertaining to one or more services; (b) storing, by said one or more physical nodes, a database comprising information pertaining to one or more service providers associated with the first organization; (c) receiving by said one or more physical nodes a first request for a service authorization for a service provider associated with a first organization to provide a service to one or more individuals in a second organization, wherein said service authorization comprises an authorization from said regulating or funding organization to provide specific services to the one or more individuals, wherein the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain, the service provider is associated with one or more roles and one or more caseloads each of the one or more individual's information in the second organization has at least one type, the one or more roles includes access privilege information for one or more service providers, and the one or more caseloads includes access privilege information for at least one individual or medical services program; (d) logging by the one or more physical nodes, in an activity log associated with at least the first organization or the second organization, the first request for said service authorization for the service provider associated with the first organization to provide said service to the one or more individuals in the second organization; (e) determining by the one or more physical nodes whether the service provider associated with the first organization has been granted a service authorization to provide said service to the one or more individuals in the second organization, wherein the determination is based on at least the access profile, the one or more caseloads and the one or more roles associated with the service provider and the type of the one or more individual's information in the second organization; (f) granting said service authorization to said requested service provider, wherein said service authorization comprises authorization from said regulating or funding organization to provide specific services to the one or more individuals; (g) responsive to determining that the service provider associated with the first organization has been granted a service authorization to provide said service to the one or more individuals in the second organization: (g)(i) transferring by the one or more physical nodes the one or more individual's information in the second organization to the service provider associated with the first organization; (g)(ii) logging by the one or more physical nodes, in the activity log, said granting of said service authorization and the transferring of the one or more individual's information in the second organization to the service associated with the first organization.

Plain English Translation

A system allows a service provider from one organization (Organization A) to access an individual's information stored in another organization (Organization B). A request is made to a regulating or funding organization for a service authorization, which allows the service provider to provide specific services. The system stores databases of available services and service providers. When a request for authorization is received, it's logged. The system checks if the service provider has the proper authorization based on access profiles, roles, caseloads and the type of information needed. If authorized, the system transfers the individual's information to the service provider and logs the transfer. The organizations are in different security domains, each with its own access profile.

Claim 2

Original Legal Text

2. The method of requesting a service authorization as claimed in claim 1 , wherein said first request for said service authorization comes from one or more of the individual, a parent or guardian of the individual, and said regulating or funding organization.

Plain English Translation

The service authorization request described in the previous system can originate from the individual whose data is being requested, their parent/guardian, or the regulating/funding organization overseeing the services. Therefore, the authorization process can be initiated by the individual needing the service, someone acting on their behalf, or the agency responsible for regulating or funding the service.

Claim 3

Original Legal Text

3. The method of requesting a service authorization as claimed in claim 1 , further comprising rejecting said request for said service authorization if said service provider associated with said first organization is not authorized to access the one or more individual's information in the second organization.

Plain English Translation

In the authorization system described previously, if the service provider from Organization A is not authorized to access the individual's information in Organization B, the service authorization request is rejected. This rejection ensures that only authorized service providers can access sensitive information, maintaining data security and privacy.

Claim 4

Original Legal Text

4. A method of requesting a service authorization as claimed in claim 1 , wherein said service provider is said first organization.

Plain English Translation

In the authorization system described previously, the service provider requesting access to the individual's data in Organization B can be Organization A itself, rather than a separate entity. This means the organization, as a whole, can request authorization to provide services and access the necessary information.

Claim 5

Original Legal Text

5. The method of requesting a service authorization as claimed in claim 1 , wherein said service provider is an individual within said first organization.

Plain English Translation

In the authorization system described previously, the service provider requesting access to an individual's information in Organization B can be a specific individual within Organization A. This allows individual service providers within an organization to request and obtain the necessary authorization.

Claim 6

Original Legal Text

6. The method of requesting a service authorization as claimed in claim 1 , further comprising: notifying, by said one or more physical nodes, said regulating or funding organization of said request for said service authorization; providing, by said one or more physical nodes, a system for secure communications to discuss and resolve said request; providing, by said one more or physical nodes, a secure system for approving or denying said service authorization request; recording, by said one or more physical nodes, discussions decisions on said service authorization request; and sharing, by said one or more physical nodes, said service authorization with the first organization and the second organization.

Plain English Translation

The authorization system also involves: notifying the regulating or funding organization about the service authorization request; providing a secure communication channel for discussing and resolving the request; providing a secure system for approving or denying the request; recording discussions and decisions related to the request; and sharing the service authorization status with both Organization A and Organization B. This ensures transparency and auditability throughout the process.

Claim 7

Original Legal Text

7. A non-transitory computer-readable storage media having computer executable code stored thereon, the code for requesting a service authorization from a regulating or funding organization for a service provider in at least a first organization to provide service to one or more individuals in a second organization, the code, when executed: (a) stores a database comprising information pertaining to one or more services; (b) stores a database comprising information pertaining to one or more service providers associated with the first organization; (c) receives a first request for a service authorization for a service provider associated with a first organization to provide said service to one or more individuals in a second organization, wherein said service authorization comprises an authorization from said regulating or funding organization to provide specific services to the one or more individuals, wherein the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain, the service provider is associated with one or more roles and one or more caseloads, each of the one or more individual's information in the second organization has at least one type, the one or more roles includes access privilege information for one or more service providers, and the one or more caseloads includes access privilege information for at least one individual or medical services program; (d) logs, in an activity log associated with at least the first organization or the second organization, the first request for said service authorization for the service provider associated with the first organization to provide said service to the one or more individuals in the second organization; (e) determines whether the service provider associated with the first organization has been granted a service authorization provide said service to the one or more individuals in the second organization, wherein the determination is based on at least the access profile, the one or more caseloads and the one or more roles associated with the service provider; and the type of the one or more individual's information in the second organization; (f) responsive to determining that the service provider associated with the first organization has been granted said service authorization to provide said service to the one or more individuals in the second organization: (f)(i) transfers the one or more individual's information in the second organization to the service provider associated with the first organization; (f)(ii) logs, in the activity log, the granting of the said service authorization and the transferring of the one or more individual's information in the second organization to the service provider associated with the first organization.

Plain English Translation

A computer program stored on a non-transitory storage medium automates the service authorization process. The program stores databases of services and service providers. When a service provider from Organization A requests access to an individual's information in Organization B, the program logs the request. It then determines if the service provider is authorized based on access profiles, roles, and caseloads. If authorized, the program transfers the individual's data to the service provider and logs the data transfer. The program manages access between two different organizations with different security domains.

Claim 8

Original Legal Text

8. The non-transitory computer-readable storage media as claimed in claim 7 , wherein said first request for said service authorization comes from one or more of the individual, a parent or guardian of the individual, and said regulating or funding organization.

Plain English Translation

The computer program in the previous description handles service authorization requests originating from the individual whose data is requested, their parent or guardian, or the regulating or funding organization responsible for overseeing the service.

Claim 9

Original Legal Text

9. The non-transitory computer-readable storage media as claimed in claim 7 , wherein said request for said service authorization is rejected if said service provider associated with said first organization is not authorized to access the one or more individual's information in the second organization.

Plain English Translation

Using the computer program described previously, if a service provider from Organization A is not authorized to access the individual's information in Organization B, the program automatically rejects the service authorization request.

Claim 10

Original Legal Text

10. The non-transitory computer-readable storage media as claimed in claim 7 , wherein said service provider is said first organization.

Plain English Translation

The computer program in the previous description allows Organization A itself, rather than a separate entity, to be the service provider requesting data access.

Claim 11

Original Legal Text

11. The non-transitory computer-readable storage media as claimed in claim 7 , wherein said service provider is an individual within said first organization.

Plain English Translation

The computer program in the previous description also allows a specific individual within Organization A to act as the service provider requesting data access.

Claim 12

Original Legal Text

12. The non-transitory computer-readable storage media as claimed in claim 7 , wherein the code: notifies said regulating or funding organization of said request for said service authorization; provides a system for secure communications to discuss and resolve said request; provides a secure system for approving or denying said service authorization request; records discussions decisions on said service authorization request; and shares said service authorization with the first organization and the second organization.

Plain English Translation

The computer program further enhances the authorization process by: notifying the regulating/funding organization about the service request; providing secure communication for discussing/resolving the request; providing a secure system for approving/denying the request; recording discussions and decisions made about the request; and sharing the final authorization status with both Organization A and Organization B.

Claim 13

Original Legal Text

13. A system for requesting a service authorization from a regulating or funding organization for a service provider in at least a first organization to provide service to one or more individuals in a second organization, the system comprising: a computer program stored in memory, which when executed by a processor performs the steps of: (a) storing a database comprising information pertaining to one or more services; (b) storing a database comprising information pertaining to one or more service providers associated with the first organization; (c) receiving a first request for a service authorization for a service provider associated with a first organization to provide a service to one or more individuals in a second organization, wherein said service authorization comprises an authorization from said regulating or funding organization to provide specific services to the one or more individuals, wherein the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain, the service provider is associated with one or more roles and one or more caseloads each of the one or more individual's information in the second organization has at least one type, the one or more roles includes access privilege information for one or more service providers, and the one or more caseloads includes access privilege information for at least one individual or medical services program; (d) logging, in an activity log associated with at least the first organization or the second organization, the first request for said service authorization for the service provider associated with the first organization to provide said service to the one or more individuals in the second organization; (c) determining whether the service provider associated with the first organization has been granted a service authorization provide said service to the one or more individuals in the second organization, wherein the determination is based on at least the access profile, the one or more caseloads and the one or more roles associated with the service provider and the type of the one or more individual's information in the second organization; (d) responsive to determining that the service provider associated with the first organization has been granted a service authorization to provide said service to the one or more individuals in the second organization: (d)(i) transferring the one or more individual's information in the second organization to the service provider associated with the first organization; (d)(ii) logging, in the activity log, the granting of said service authorization and the transferring of the one or more individual's information in the second organization to the service provider associated with the first organization.

Plain English Translation

A system for requesting service authorization between two organizations includes a computer program which: (a) stores a database of services; (b) stores a database of service providers in the first organization; (c) receives a request for service authorization for a service provider from the first organization to provide service to an individual in the second organization, where the first and second organization have different security domains; (d) logs the service authorization request in an activity log; (e) determines if the service provider has been granted authorization based on access profile, caseload, roles and type of information; (f) if authorization is granted, transfers the individuals information to the service provider and logs the granting of the service authorization and transfer of information in the activity log.

Claim 14

Original Legal Text

14. The system for requesting a service authorization as claimed in claim 13 , wherein said first request for said service authorization comes from one or more of the individual, a parent or guardian of the individual, and said regulating or funding organization.

Plain English Translation

The system described above can receive the service authorization request from the individual, a parent or guardian of the individual, or the regulating or funding organization.

Claim 15

Original Legal Text

15. The system for requesting a service authorization as claimed in claim 13 , wherein said request for said service authorization is rejected if said service provider associated with said first organization is not authorized to access the one or more individual's information in the second organization.

Plain English Translation

The system described above will reject the service authorization request if the service provider from the first organization is not authorized to access the individual's information in the second organization.

Claim 16

Original Legal Text

16. The system for requesting a service authorization as claimed in claim 13 , wherein said service provider is said first organization.

Plain English Translation

The system described above permits the first organization itself to be the service provider.

Claim 17

Original Legal Text

17. The system for requesting a service authorization as claimed in claim 13 , wherein said service provider is an individual within said first organization.

Plain English Translation

The system described above permits an individual within the first organization to be the service provider.

Claim 18

Original Legal Text

18. The system for requesting a service authorization as claimed in claim 13 , wherein said computer program, when executed by a processor, performs the steps of: notifying said regulating or funding organization of said request for said service authorization; providing a system for secure communications to discuss and resolve said request; providing a secure system for approving or denying said service authorization request; recording discussions decisions on said service authorization request; and sharing said service authorization with the first organization and the second organization.

Plain English Translation

The system described above further includes notifying the regulating or funding organization of the request, providing a system for secure communications to discuss and resolve the request, providing a secure system for approving or denying the request, recording discussions/decisions regarding the request, and sharing the service authorization with the first and second organizations.

Claim 19

Original Legal Text

19. A method of requesting a service authorization from a regulating or funding organization for a service provider in at least a first organization to provide service to one or more individuals in a second organization, the method comprising: (a) storing, by one or more physical nodes, a database comprising information pertaining to one or more services; (b) storing, by said one or more physical nodes, a database comprising information pertaining to one or more service providers associated with the first organization; (c) requesting a service authorization for a service provider associated with a first organization to provide a service to one or more individuals in a second organization, wherein the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain; (d) comparing said requested service provider with said database of said information pertaining to one or more service providers to determine if said requested service provider has been authorized by the one or more individuals; (e) granting a service authorization to said requested service provider, wherein said service authorization comprises authorization from said regulating or funding organization to provide specific services to the one or more individuals; (f) receiving by said one or more physical nodes a first request for authorization for said service provider associated with a first organization to access one or more individual's information in a second organization, wherein the first request for authorization includes authorization to access one or more of the one or more individual's name, social security number, state identification number, birth date, home address, and Medicaid number, the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain, the service provider associated with the first organization is associated with one or more roles and one or more caseloads, the one or more individual's information in the second organization has at least one type, the one or more roles includes access privilege information for one or more service providers, and the one or more caseloads includes access privilege information for at least one individual or medical services program; (g) logging by the one or more physical nodes, in an activity log associated with at least the first organization or the second organization, the first request for authorization for the service provider associated with the first organization to access the one or more individual's information in the second organization; (h) determining by said one or more physical nodes whether the one or more individual's information in the second organization is accessible based on the one or more of the one or more individual's name, social security number, state identification number, birth date, and Medicaid number; (i) responsive to determining that the individual's information in the second organization is accessible based on the one or more of the one or more individual's name, social security number, state identification number, birth date, and Medicaid number: (i)(i) determining by the one or more physical nodes whether the service provider associated with the first organization has been granted authorization to access the one or more individual's information in the second organization, wherein the determination is based on at least the access profile, the one or more caseloads and one or more roles associated with the service provider, and the type of the individual's information in the second organization; (i)(ii) responsive to determining that the service provider associated with the first organization has been granted a authorization to access the one or more individual's information in the second organization: (i)(ii)(A) transferring by the one or more physical nodes the one or more individual's information in the second organization to the service provider; (i)(ii)(B) logging by the one or more physical nodes, in the activity log, the granting of said service authorization and the transferring of the one or more individual's information in the second organization to the service provider.

Plain English Translation

A system facilitates secure data sharing between organizations. It stores databases of services and service providers. When Organization A seeks access to an individual's data in Organization B, a service authorization is requested. The system verifies the service provider against its database to check individual authorization. If authorized, access is granted by the regulating body. A request with access to specific sensitive data (name, SSN, etc.) is logged. The system determines data accessibility based on this sensitive information. Access is granted only if the individual's information is deemed accessible, the service provider is authorized based on access profiles, and roles, leading to data transfer, which is logged. The organizations exist in separate security domains.

Claim 20

Original Legal Text

20. A method of requesting a service authorization as claimed in claim 19 , wherein said request for said service authorization comes from one or more of the individual, a parent or guardian of the individual, and said regulating or funding organization.

Plain English Translation

The service authorization request described above can come from the individual whose data is being requested, their parent/guardian, or the regulating/funding organization.

Claim 21

Original Legal Text

21. A method of requesting a service authorization as claimed in claim 19 , further comprising rejecting said request for said service authorization if said service provider associated with said first organization is not authorized to access the one or more individual's information in the second organization.

Plain English Translation

The system will reject the service authorization request if the service provider from the first organization is not authorized to access the individual's information in the second organization.

Claim 22

Original Legal Text

22. A method of requesting a service authorization as claimed in claim 19 , wherein said service provider is said first organization.

Plain English Translation

The service provider requesting access can be Organization A itself, rather than a separate entity.

Claim 23

Original Legal Text

23. The method of requesting a service authorization as claimed in claim 19 , wherein said service provider is an individual within said first organization.

Plain English Translation

A specific individual within Organization A can be the service provider requesting access.

Claim 24

Original Legal Text

24. A method of requesting a service authorization as claimed in claim 19 , further comprising: notifying, by said one or more physical nodes, said regulating or funding organization of said request for said service authorization; providing, by said one or more physical nodes, a system for secure communications to discuss and resolve said request; providing, by said one more or physical nodes, a secure system for approving or denying said service authorization request; recording, by said one or more physical nodes, discussions decisions on said service authorization request; and sharing, by said one or more physical nodes, said service authorization with the first organization and the second organization.

Plain English Translation

The system also notifies the regulating/funding organization about the service authorization request, provides a secure communication channel, a secure system for approving/denying the request, records related discussions and decisions, and shares the authorization status with both organizations.

Claim 25

Original Legal Text

25. A non-transitory computer-readable storage media having computer executable code stored thereon, the code for requesting a service authorization from a regulating or funding organization for a service provider in at least a first organization to provide service to one or more individuals in a second organization, the code, when executed: (a) stores a database comprising information pertaining to one or more services; (b) stores a database comprising information pertaining to one or more service providers associated with the first organization; (c) requests a service authorization for a service provider associated with a first organization to provide a service to one or more individuals in a second organization, wherein the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain; (d) compares said requested service provider with said database of said information pertaining to one or more service providers to determine if said requested service provider has been authorized by the one or more individuals; (e) grants a service authorization to said requested service provider, wherein said service authorization comprises authorization from said regulating or funding organization to provide specific services to the one or more individuals; (f) receives a first request for authorization for a service provider associated with a first organization to access one or more individual's information in a second organization, wherein the first request for authorization includes one or more of the one or more individual's name, social security number, state identification number, birth date, home address, and Medicaid number, the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain, the service provider associated with the first organization is associated with one or more roles and one or more caseloads, each of the one or more individual's information in the second organization has at least one type, the one or more roles includes access privilege information for one or more service providers, and the one or more caseloads includes access privilege information for at least one individual or medical services program; (g) logs, in an activity log associated with at least the first organization or the second organization, the first request for authorization for the service provider associated with the first organization to access the one or more individual's information in the second organization; (h) determines whether the one or more individual's information in the second organization is accessible based on at least the access profile, the one or more of the one or more individual's name, social security number, state identification number, birth date, and Medicaid number; (i) responsive to determining that the individual's information in the second organization is accessible based on the one or more of the one or more individual's name, social security number, state identification number, birth date, and Medicaid number: (i)(i) determines whether the service provider associated with the first organization has been granted authorization to access the one or more individual's information in the second organization, wherein the determination is based at least the access profile, on the one or more caseloads and one or more roles associated with the service provider, and the type of the individual's information in the second organization; (i)(ii) responsive to determining that the service provider associated with the first organization has been granted authorization to access the one or more individual's information in the second organization: (i)(ii)(A) transfers the one or more individual's information in the second organization to the servicer; (i)(ii)(B) logs, in the activity log, the granting of said service authorization and the transferring of the one or more individual's information in the second organization to the service provider.

Plain English Translation

A computer-readable storage medium contains code that automates a secure data-sharing system between organizations. The code stores databases of services and service providers. When a service authorization is requested by Organization A for access to an individual's data in Organization B, the code verifies the service provider's authorization. If initially authorized, the code processes a data access request, including sensitive details like name and SSN. The system then logs the request, and determines data accessibility based on sensitive information. Access is only granted if the data is deemed accessible, and the service provider is authorized based on access profiles and roles. This results in data transfer, logged for security purposes. The organizations exist in different security domains.

Claim 26

Original Legal Text

26. The non-transitory computer-readable storage media as claimed in claim 25 , wherein said request for said service authorization comes from one or more of the individual, a parent or guardian of the individual, and said regulating or funding organization.

Plain English Translation

The computer program, as described in the previous system, can handle service authorization requests originating from the individual whose data is requested, their parent or guardian, or the regulating or funding organization.

Claim 27

Original Legal Text

27. The non-transitory computer-readable storage media as claimed in claim 25 , wherein said request for said service authorization is rejected if said service provider associated with said first organization is not authorized to access the one or more individual's information in the second organization.

Plain English Translation

The computer program will automatically reject the service authorization request if the service provider is unauthorized.

Claim 28

Original Legal Text

28. The non-transitory computer-readable storage media as claimed in claim 25 , wherein said service provider is said first organization.

Plain English Translation

The computer program in the previous description allows Organization A itself, rather than a separate entity, to be the service provider requesting data access.

Claim 29

Original Legal Text

29. The non-transitory computer-readable storage media as claimed in claim 25 , wherein said service provider is an individual within said first organization.

Plain English Translation

The computer program in the previous description also allows a specific individual within Organization A to act as the service provider requesting data access.

Claim 30

Original Legal Text

30. The non-transitory computer-readable storage media as claimed in claim 25 , wherein the code: notifies said regulating or funding organization of said request for said service authorization; provides a system for secure communications to discuss and resolve said request; provides a secure system for approving or denying said service authorization request; records discussions decisions on said service authorization request; and shares said service authorization with the first organization and the second organization.

Plain English Translation

The computer program further enhances the authorization process by: notifying the regulating or funding organization; providing secure communication channels; offering a secure approval/denial system; documenting discussions and decisions made; and disseminating the final authorization status to both involved organizations.

Claim 31

Original Legal Text

31. A system for requesting a service authorization from a regulating or funding organization for a service provider in at least a first organization to provide service to one or more individuals in a second organization, the system comprising: a computer program stored in memory, which when executed by a processor performs the steps of: (a) storing, by one or more physical nodes, a database comprising information pertaining to one or more services; (b) storing, by said one or more physical nodes, a database comprising information pertaining to one or more service providers associated with the first organization; (c) requesting a service authorization for a service provider associated with a first organization to provide a service to one or more individuals in a second organization, wherein the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain; (d) comparing said requested service provider with said database of said information pertaining to one or more service providers to determine if said requested service provider has been authorized by the one or more individuals; (e) granting a service authorization to said requested service provider, wherein said service authorization comprises authorization from said regulating or funding organization to provide specific services to the one or more individuals; (f) receiving by said one or more physical nodes a first request for authorization for said service provider associated with a first organization to access one or more individual's information in a second organization, wherein the first request for authorization includes one or more of the one or more individual's name, social security number, state identification number, birth date, home address, and Medicaid number, the first organization is associated with a first security domain, the second organization is associated with a second security domain, the second organization has an access profile associated with the first security domain, the service provider associated with the first organization is associated with one or more roles and one or more caseloads, each of the one or more individual's information in the second organization has at least one type, the one or more roles includes access privilege information for one or more service providers, and the one or more caseloads includes access privilege information for at least one individual or medical services program; (d) logging, in an activity log associated with at least the first organization or the second organization, the first request for authorization for the service provider associated with the first organization to access the one or more individual's information in the second organization; (e) determining whether the one or more individual's information in the second organization is accessible based on the one or more of the one or more individual's name, social security number, state identification number, birth date, and Medicaid number; (f) responsive to determining that the individual's information in the second organization is accessible based on the one or more of the one or more individual's name, social security number, state identification number, birth date, and Medicaid number: (d)(i) determining whether the service provider associated with the first organization has been granted authorization to access the one or more individual's information in the second organization, wherein the determination is based on at least the access profile, the one or more caseloads and one or more roles associated with the service provider, and the type of the individual's information in the second organization; (d)(ii) responsive to determining that the service provider associated with the first organization has been granted authorization to access the one or more individual's information in the second organization: (d)(ii)(A) transferring the one or more individual's information in the second organization to the service provider; (d)(ii)(B) logging, in the activity log, the granting of said service authorization and the transferring of the one or more individual's information in the second organization to the service provider.

Plain English Translation

A system for requesting service authorization between two organizations includes a computer program which: (a) stores a database of services; (b) stores a database of service providers in the first organization; (c) requests a service authorization for a service provider from the first organization to provide service to an individual in the second organization, where the first and second organization have different security domains; (d) compares the requested service provider with the database of service providers to determine if the service provider has been authorized by the individual; (e) grants a service authorization to the service provider, where the service authorization comprises authorization from the regulating or funding organization; (f) receives a request for authorization for the service provider to access sensitive data of the individual; (g) logs the service authorization request in an activity log; (h) determines if the data is accessible based on parameters like name, SSN, etc.; (i) if the data is accessible, determines if the service provider has been granted authorization to access the individual’s information. If authorization has been granted, the information is transferred and logged.

Claim 32

Original Legal Text

32. The system for requesting a service authorization as claimed in claim 31 , wherein said request for said service authorization comes from one or more of the individual, a parent or guardian of the individual, and said regulating or funding organization.

Plain English Translation

The system described above can receive the service authorization request from the individual, a parent or guardian of the individual, or the regulating or funding organization.

Claim 33

Original Legal Text

33. The system for requesting a service authorization as claimed in claim 31 , wherein said request for said service authorization is rejected if the individual is not authorized to access the one or more individual's information in the second organization.

Plain English Translation

The system described above will reject the service authorization request if the individual is not authorized to access the individual's information in the second organization.

Claim 34

Original Legal Text

34. The system for requesting a service authorization as claimed in claim 31 , wherein said service provider is said first organization.

Plain English Translation

The system described above permits the first organization itself to be the service provider.

Claim 35

Original Legal Text

35. The system for requesting a service authorization as claimed in claim 31 , wherein said service provider is an individual within said first organization.

Plain English Translation

The system described above permits an individual within the first organization to be the service provider.

Claim 36

Original Legal Text

36. The system for requesting a service authorization as claimed in claim 31 , wherein said computer program, when executed by a processor, performs the steps of: notifying said regulating or funding organization of said request for said service authorization; providing a system for secure communications to discuss and resolve said request; providing a secure system for approving or denying said service authorization request; recording discussions decisions on said service authorization request; and sharing said service authorization with the first organization and the second organization.

Plain English Translation

The system described above further includes notifying the regulating or funding organization of the request, providing a system for secure communications to discuss and resolve the request, providing a secure system for approving or denying the request, recording discussions/decisions regarding the request, and sharing the service authorization with the first and second organizations.

Patent Metadata

Filing Date

Unknown

Publication Date

October 17, 2017

Inventors

Richard Allen Robbins
Warren Stanton Gifford
Mojahedul Hoque Abul Hassanat
Bradley Drew Turock
Justin Mark Brockie
James Michael Kelly
Zaiur Rahman

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, FAQs, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “Managing Secure Sharing of Private Information Across Security Domains by Individuals Having a Service Authorization” (9794257). https://patentable.app/patents/9794257

© 2026 Nomic Interactive Technology LLC. Machine-readable context available at /api/llm-context/9794257. See llms.txt for full attribution policy.

Managing Secure Sharing of Private Information Across Security Domains by Individuals Having a Service Authorization